9.8
CVSSv3

CVE-2023-42470

Published: 11/09/2023 Updated: 13/09/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Imou Life com.mm.android.smartlifeiot application up to and including 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs.

Vulnerable Product Search on Vulmon Subscribe to Product

imoulife life